2026 CVE Vulnerabilities

43,225 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-61486CRITICAL9.8** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in Apache Lucy. This issue affects Apache Luc...
CVE-2026-61484CRITICAL9.8** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy. This issue affects Apac...
CVE-2026-5581CRITICAL9.1The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to unauthorized arbitrary media deletion in all ...
CVE-2026-4431CRITICAL9.1The Easy Post Submission plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi...
CVE-2026-16940CRITICAL10The Custom Fields WordPress plugin before 1.5.1 does not validate a user-supplied file path before deletion, allowing un...
CVE-2026-15360CRITICAL9.1The Ajax Load More WordPress plugin before 8.0.1 does not properly sanitise and escape a parameter before using it in a...
CVE-2026-15210CRITICAL9.1The OTP Login With Phone Number, OTP Verification WordPress plugin before 1.8.71 does not limit the number of OTP verifi...
CVE-2026-9273CRITICAL9.3The Membership Plugin – Kadence Memberships plugin for WordPress (formerly Restrict Content) is vulnerable to password r...
CVE-2026-45537CRITICAL9.1OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the con...
CVE-2026-45100CRITICAL9.1OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions 3.4.0-beta through 3.6.5 and 4.0.0-beta ...
CVE-2026-70554CRITICAL9.8MaxSite CMS contains a PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary cod...
CVE-2026-67979CRITICAL9.1Incorrect access control in the Executive Services dynamic application start path component of NASA cFS v7.0.1 allows at...
CVE-2026-66902CRITICAL9.8Google::Auth versions before 0.06 for Perl run a command named in an external_account credentials JSON via an ungated sy...
CVE-2026-45538CRITICAL9.8OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions 4.0.0 and prior, processing a SIP mes...
CVE-2026-70553CRITICAL9.8MaxSite CMS contains a remote code execution vulnerability that allows unauthenticated attackers to inject arbitrary PHP...
CVE-2026-70552CRITICAL9.8MaxSite CMS 109.5 and earlier contains an authentication bypass vulnerability in the AJAX dispatcher that allows unauthe...
CVE-2026-70478CRITICAL9.2Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the POST /api/v...
CVE-2026-70477CRITICAL9.5Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, a prompt inject...
CVE-2026-69703CRITICAL9.8Atlas-Livre contains an improper access control vulnerability in the admin controllers under Espace_admin/controleur/ th...
CVE-2026-49435CRITICAL9.8Keysight IxChariot Endpoint and associated products contain a stack-based buffer overflow. An unauthenticated remote att...
CVE-2026-0163CRITICAL9.8In multiple functions of vpu_ioctl.c, there is a possible use after free due to a use after free. This could lead to rem...
CVE-2026-70470CRITICAL9.5Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise validat...
CVE-2026-69264CRITICAL9.4Prior to 3.1.3, Flowise CSVAgent interpolates an attacker-controlled segment of the csvFile data URI directly into a Pyt...
CVE-2026-24254CRITICAL9.8NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attacker could cause an ou...
CVE-2026-69259CRITICAL9.4Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the SQLite Reco...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now